jetty-server: Improper release of ByteBuffers in SslConnections
Published Jul 7, 2022
7.5
HIGHCVSS 3.1
EPSS 2.18%
Description
In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.
Affected products
-
- Version 10.0.0StatusaffectedConstraints<unspecified
- Version 11.0.0StatusaffectedConstraints<unspecified
- Version unspecifiedStatusaffectedConstraints<=10.0.9
- Version unspecifiedStatusaffectedConstraints<=11.0.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| The Eclipse Foundation | Eclipse Jetty | n/a |
|
No data.
Red Hat AMQ Streams 2.3.0
jetty-server
Fixed · RHSA-2023:0189
A-MQ Clients 2
jetty-server
Not affected
Red Hat AMQ Broker 7
jetty-server
Not affected
Red Hat Data Grid 8
jetty-server
Not affected
Red Hat Decision Manager 7
jetty-server
Not affected
Red Hat Fuse 7
jetty-server
Not affected
Red Hat Integration Camel K 1
jetty-server
Not affected
Red Hat Integration Camel Quarkus 1
jetty-server
Not affected
Red Hat JBoss Data Grid 7
jetty-server
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
jetty-server
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jetty-server
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
jetty-server
Not affected
Red Hat JBoss Fuse 6
jetty-server
Out of support scope
Red Hat JBoss Fuse Service Works 6
jetty-server
Out of support scope
Red Hat OpenShift Application Runtimes
jetty-server
Not affected
Red Hat OpenStack Platform 13 (Queens)
opendaylight
Out of support scope
Red Hat Process Automation 7
jetty-server
Not affected
Red Hat Satellite 6
lucene4
Not affected
Red Hat Satellite 6
puppetserver
Not affected
Red Hat build of Apicurio Registry 2
jetty-server
Not affected
Red Hat build of Debezium 1
jetty-server
Not affected
Red Hat build of Quarkus
jetty-server
Not affected
Red Hat support for Spring Boot
jetty-server
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AMQ Streams 2.3.0 | jetty-server | Fixed | RHSA-2023:0189 |
| A-MQ Clients 2 | jetty-server | Not affected | n/a |
| Red Hat AMQ Broker 7 | jetty-server | Not affected | n/a |
| Red Hat Data Grid 8 | jetty-server | Not affected | n/a |
| Red Hat Decision Manager 7 | jetty-server | Not affected | n/a |
| Red Hat Fuse 7 | jetty-server | Not affected | n/a |
| Red Hat Integration Camel K 1 | jetty-server | Not affected | n/a |
| Red Hat Integration Camel Quarkus 1 | jetty-server | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | jetty-server | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | jetty-server | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jetty-server | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jetty-server | Not affected | n/a |
| Red Hat JBoss Fuse 6 | jetty-server | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | jetty-server | Out of support scope | n/a |
| Red Hat OpenShift Application Runtimes | jetty-server | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | opendaylight | Out of support scope | n/a |
| Red Hat Process Automation 7 | jetty-server | Not affected | n/a |
| Red Hat Satellite 6 | lucene4 | Not affected | n/a |
| Red Hat Satellite 6 | puppetserver | Not affected | n/a |
| Red Hat build of Apicurio Registry 2 | jetty-server | Not affected | n/a |
| Red Hat build of Debezium 1 | jetty-server | Not affected | n/a |
| Red Hat build of Quarkus | jetty-server | Not affected | n/a |
| Red Hat support for Spring Boot | jetty-server | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
In Red Hat Satellite 6.9 we are using 9.4.x or below of jetty-server. Red Hat Satellite 6.10 is not using jetty-server anymore. This flaw only affects versions above 10.0.x or 11.0.x of jetty-server, therefore Red Hat Satellite 6.9 or 6.10 are not impacted by this vulnerability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.18% (0.02178) | 81.68th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.67% (0.01672) | 73.71th | v5 (v2026.06.15) |
| May 18, 2026 | 1.61% (0.01609) | 81.97th | v4 (v2025.03.14) |
| Nov 21, 2025 | 0.53% (0.00525) | 66.15th | v4 (v2025.03.14) |
| Nov 18, 2025 | 2.00% (0.02002) | 82.22th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.49% (0.00488) | 62.66th | v4 (v2025.03.14) |
| Mar 29, 2025 | 27.18% (0.27181) | 94.22th | v4 (v2025.03.14) |
| Mar 24, 2025 | 0.49% (0.00488) | 62.73th | v4 (v2025.03.14) |
| Mar 23, 2025 | 6.31% (0.06306) | 89.28th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.49% (0.00488) | 63.38th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.13% (0.00128) | 49.23th | v3 (v2023.03.01) |
| Jan 28, 2024 | 0.13% (0.00128) | 47.43th | v3 (v2023.03.01) |
| Dec 18, 2023 | 0.12% (0.00123) | 46.51th | v3 (v2023.03.01) |
| Aug 9, 2023 | 0.11% (0.00112) | 43.58th | v3 (v2023.03.01) |
| Jul 14, 2023 | 0.10% (0.00099) | 40.30th | v3 (v2023.03.01) |
| Jul 3, 2023 | 0.07% (0.00071) | 28.96th | v3 (v2023.03.01) |
| Jun 7, 2023 | 0.05% (0.00051) | 17.68th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 10.98th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 9, 2023 | 0.89% (0.00885) | 27.47th | v2 (v2022.01.01) |
| Jul 8, 2022 | 0.89% (0.00885) | 25.47th | v2 (v2022.01.01) |
References (8)
- https://access.redhat.com/security/cve/CVE-2022-2191 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2116953 Issue Tracking
- https://github.com/advisories/GHSA-8mpp-f3f7-xc28 Advisory
- https://github.com/eclipse/jetty.project/issues/8161
- https://github.com/eclipse/jetty.project/security/advisories/GHSA-8mpp-f3f7-xc28 x_refsource_CONFIRMExploitVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2191
- https://security.netapp.com/advisory/ntap-20220909-0003/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-2191
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2191 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2116953 | Issue Tracking | |
| https://github.com/advisories/GHSA-8mpp-f3f7-xc28 | Advisory | |
| https://github.com/eclipse/jetty.project/issues/8161 | ||
| https://github.com/eclipse/jetty.project/security/advisories/GHSA-8mpp-f3f7-xc28 | x_refsource_CONFIRMExploitVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-2191 | ||
| https://security.netapp.com/advisory/ntap-20220909-0003/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-2191 |
Change history (0)
No recorded changes yet.